
CVE-2025-52204: Reflected XSS / HTML Injection in Znuny OTRS
customer.pl endpointA Reflected Cross-Site Scripting (XSS) and HTML Injection vulnerability exists in Znuny, allowing attackers to inject arbitrary JavaScript or HTML via the parameter defined by the system configuration CustomerPanelSessionName in the customer.pl endpoint.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NSuccessful exploitation may allow an unauthenticated remote attacker to:
The issue was also observed during research on publicly exposed real-world instances running:
To avoid unnecessarily exposing third-party systems, specific targets, URLs, and validation screenshots from those instances are intentionally omitted from this public repository.
During testing and research, the following request patterns were observed:
6.5.9 - 6.5.18: /otrs/customer.pl?OTRSCustomerInterface=$PAYLOAD7.0.11 - 7.2.3: /znuny/customer.pl?OTRSCustomerInterface=$PAYLOADThese are observed request patterns and may vary depending on product branch and installation layout.
The affected input is the one defined by the CustomerPanelSessionName system configuration. In observed deployments, this may appear as OTRSCustomerInterface, depending on the system configuration.
The vendor addressed this issue in:


Administrators should upgrade to the vendor-fixed versions:
Additional good practices include:
customer.plThis repository documents a coordinated vulnerability disclosure process.
It intentionally does not include:
The goal is to preserve technical accuracy while minimizing unnecessary risk to third parties.